Privacy policy

Data protection declaration and information for data subjects in accordance with Article 13 and Article 14 of the EU General Data Protection Regulation

General information


Responsible office

The controller for the collection, processing and use of your personal data within the meaning of the DSGVO is

Business: fein.media GmbH / Rock Shop
Legal representative: Gerd Gruss
Adress: Am Sandfeld 21, 76149 Karlsruhe
Contact data protection officer: datenschutz@rockshop.de

General information on data processing

We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the fein.media GmbH. The security of your data is important to us. That is why the protection of your privacy is of particular concern to us. The collection and processing of your personal data, for example your name, address, e-mail address or telephone number, is always carried out in compliance with the applicable data protection regulations, in particular the EU General Data Protection Regulation (DSGVO).

This statement describes how and for what purpose your data is collected and used and what choices you have in connection with personal data. Furthermore, data subjects are informed of their rights by means of this privacy policy.

As the controller, fein.media has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. Nevertheless, Internet-based data transmissions may in principle have security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.

By using this website, you consent to the collection, use and transfer of your data in accordance with this privacy policy.

Affected data

Personal data is only collected if you provide it to us voluntarily. No other personal data is collected. Any processing of your personal data that goes beyond the scope of the statutory permissions will only take place on the basis of your express consent.

Processing purpose: Contract execution
Recipient categories: Public authorities if overriding legal provisions apply. Other external bodies if the data subject has given their consent or transmission is permitted for reasons of overriding interest.
Third country transfers: Processors outside the European Union may also be used in the performance of the contract.
Duration of data storage: The duration of data storage depends on the statutory retention obligations and is generally 10 years.

Access data

You can visit our website without providing any personal data. We only collect data about access to our website on the basis of our legitimate interest (see Art. 6 para. 1 lit. f. GDPR). We store and use data about every access to our online offer (so-called server log files). We automatically collect information about your usage behavior and your interaction with us and register data about your computer or mobile device. The access data includes the name and URL of the website accessed, the date and time of access, the amount of data transferred, notification of successful access (HTTP response code), browser type and version, operating system, referrer URL (i.e. the previously visited page), IP address and the requesting provider.
This data is merged with the usage data of all visitors to our website. We use this log data without allocation to your person or other profiling for statistical evaluations for the purpose of operation, security and optimization of our offer, but also for anonymous recording of the number of visitors to our website and the extent and type of use of our website and services, as well as for billing purposes to measure the number of clicks received from cooperation partners. Based on this information, we can provide personalized and location-based content and analyze traffic, troubleshoot and fix errors, and improve our services. We reserve the right to check the log data retrospectively if there is a justified suspicion of unlawful use based on concrete evidence. We store IP addresses in the log files for a limited period of time if this is necessary for security purposes or for the provision or billing of a service, e.g. if you use one of our offers. After canceling the order process or after receipt of payment, we delete the IP address if it is no longer required for security purposes. We also store IP addresses if we have a concrete suspicion of a criminal offense in connection with the use of our website. We also store the date of your last visit as part of your account (e.g. when registering, logging in, clicking on links, etc.).


Handling contact details

If you contact fein.media / Rock Shop via the contact options offered (e.g. via contact form or e-mail), your details will be stored so that they can be used to process and respond to your inquiry. We only store and use other personal data if you consent to this or if this is legally permissible without special consent. This data will not be passed on to third parties without your consent.


Handling comments and contributions

If you leave a post or comment on our website, your IP address will be stored. This is done on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR. GDPR and serves the security of us as the website operator: Because if your comment violates applicable law, we can be prosecuted for it, which is why we have an interest in the identity of the comment or post author.


Personal data

We use your personal data only for the purpose requested by you and without your separate consent exclusively for the fulfillment and processing of your order or service request. Once the contract has been fully processed and the purchase price has been paid in full, your data will be blocked for further use and deleted after expiry of the retention periods under tax and commercial law, unless you have expressly consented to the further use of your data.


Disclosure of personal data

We will not pass on your data to third parties without your express consent. The only exceptions to this are our service partners with whom we work together to process the contractual relationship. This applies, for example, to the transfer of your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of the goods. In order to process payments, we pass on your payment data to the credit institution commissioned with the payment. Data will only be passed on if it is required to fulfill your order. However, we will also pass on personal data to third parties if we are legally obliged to do so.


Cookies

Like many other commercial websites, fein.media / Rock Shop uses cookies in several places to collect data about how you use the website and to ensure that your visit runs smoothly. Cookies are small text files that are stored on your computer and saved by your browser. They are used to make our website more user-friendly, effective and secure. Furthermore, cookies enable our systems to recognize your browser and offer you services. Cookies do not contain any personal data. However, cookies enable us to recognize you when you visit our website at a later date. If you do not want your browser to accept cookies, you can disable this option in your browser settings. Disabling the cookie function may prevent this website from working properly. You may not be able to access all the features and information on this website.


Google Analytics

On our websites fein.media / Rock Shop uses Google Analytics, a web analysis service of Google Inc. (“Google”), to optimize and analyze our online offer within the meaning of Art. 6 para. 1 lit. f. GDPR. GDPR. Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about the use of this website by site visitors is usually transmitted to a Google server in the USA and stored there.
However, if IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. IP anonymization is active on this website. Google will use this information on our behalf to evaluate your use of the website, to compile reports on website activity and to provide us with other services relating to website activity and internet usage.

The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also use a browser plug-in to prevent the information collected by cookies (including your IP address) from being sent to Google Inc. and used by Google Inc. The following link will take you to the corresponding plugin: https://tools.google.com/dlpage/gaoptout?hl=de

Alternatively, you can prevent Google Analytics from collecting data about you within this website by clicking on this link Deactivate Google Analytics. Click on the link above to download an “opt-out cookie”. Your browser must therefore allow the storage of cookies. If you delete your cookies regularly, you will need to click on the link again each time you visit this website.

Here you will find further information on the use of data by Google Inc:

• Daten, die von Google-Partnern erhoben werden
• Einstellungen über Werbung, die Ihnen angezeigt wird
• Verwendung von Cookies in Anzeigen


Social-Media-Plugins

Facebook

Due to our legitimate interest in the analysis, optimization and operation of our online offer (within the meaning of Art. 6 para. 1 lit. f. GDPR), we use plugins of the social network facebook.com, which is operated by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). Information on all Facebook plugins can be found via the following link: https://developers.facebook.com/docs/plugins/

Facebook Inc. complies with European data protection law and is certified under the Privacy Shield Agreement: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active

The plugin establishes a direct connection between your browser and the Facebook servers. The website operator has no influence whatsoever on the nature and scope of the data that the plugin transmits to the Facebook Inc. servers. You can find information on this here: https://www.facebook.com/help/186325668085084

The plugin informs Facebook Inc. that you as a user have visited this website. There is a possibility that your IP address will be stored. If you are logged into your Facebook account during your visit to this website, this information will be linked to it.

If you use the functions of the plugin - for example by sharing or “liking” a post - the corresponding information will also be transmitted to Facebook Inc. If you would like to prevent Facebook. Inc. from linking this data to your Facebook account, please log out of Facebook before visiting this website and delete the stored cookies. You can make further settings for data processing for advertising purposes or object to the use of your data for advertising purposes via your Facebook profile. You can access the settings here:

• Profileinstellungen bei Facebook
• Cookie-Deaktivierungsseite der US-amerikanischen Website
• Cookie-Deaktivierungsseite der europäischen Website

You can find out what data, for what purpose and to what extent Facebook collects, uses and processes data and what rights and settings options you have to protect your privacy in Facebook's privacy policy. You can find it here: https://www.facebook.com/about/privacy/

Twitter

The functions of the Twitter service are integrated on our website. Twitter is a social media portal of the company Twitter Inc, 795 Folsom St., Suite 600, San Francisco, CA 94107, (USA). We use Twitter plugins. When you call up a corresponding website that contains such a plugin, data is exchanged with the Twitter servers located in the USA. Even in the case of interactions that are possible with the various Twitter plugins, the corresponding information about you is collected and transmitted to Twitter and stored. If you are also a member of Twitter and logged in to Twitter at the time you use the plugin, the information collected about your website visit will be linked to your Twitter account and made known to other users. If you do not want Twitter to link and merge the information with the data from your Twitter account, you must log out of Twitter before visiting our website. Further information on the collection and use of data by Twitter can be found at: twitter.com/privacy?lang=de.

Newsletter

If you like, we will be happy to keep you up to date. If you would like to subscribe to our newsletter, you must provide a valid e-mail address. By subscribing to the newsletter, you agree to receive the newsletter and the procedures explained. Do you no longer wish to receive the newsletter in future? You can unsubscribe from the newsletter via a link in every newsletter you receive from us. Alternatively, you can also inform us by sending us an informal message. Please use the contact details provided in our legal notice. We will then immediately delete your e-mail address from our mailing list.

Information on other data processing methods

Specific information on the processing of customer data/prospect data

Affected data: Data provided for the performance of the contract; any additional data for processing on the basis of your express consent.
Processing purpose: Contract execution, including offers, orders, sales and invoicing, quality assurance. Categories of recipients: Public authorities in the event of overriding legal provisions
Categories of recipients: External service providers or other contractors, e.g. for data processing and hosting, for shipping, transport and logistics, service providers for printing and sending information and call centers. Other external bodies insofar as the data subject has given their consent or transmission is permitted for reasons of overriding interest, e.g. for credit information for purchases on account, for the electronic dispatch of information, for quality assurance purposes.
Third country transfers: Processors outside the European Union, including email providers, may also be used as part of the execution of the contract.
Data storage duration: The duration of data storage depends on the statutory retention obligations and is generally 10 years.

Specific information on the application procedure

Affected data: Application details
Processing purpose: Implementation of the application procedure.
Categories of recipients: Public authorities in the event of overriding legal provisions. External service providers or other contractors, e.g. for data processing and hosting. Other external bodies insofar as the data subject has given their consent or transmission is permitted for reasons of overriding interest, including customers and interested parties in the context of order acquisition.
Third country transfers: Processors outside the European Union, including email providers, may also be used as part of the execution of the contract.
Data storage duration: Application data will generally be deleted within four months of notification of the decision, unless consent has been given for longer data storage in the context of inclusion in the applicant pool.

Specific information on the processing of employee data

Affected data: Data provided for the performance of the contract; any additional data for processing on the basis of your express consent.
Processing purpose: Contract performance within the scope of the employment relationship.
Categories of recipients: Public authorities in the event of overriding legal provisions, including the tax office, social security institutions, employers' liability insurance association. External service providers or other contractors, e.g. for data processing and hosting, payroll accounting, travel expense accounting, insurance services, vehicle use. Other external bodies insofar as the data subject has given their consent or transmission is permitted for reasons of overriding interest, e.g. for order acquisition, insurance services.
Third country transfers: Processors outside the European Union, including email providers, may also be used as part of the execution of the contract.
Data storage duration: The duration of data storage depends on the statutory retention obligations and is generally 10 years.

Specific information on the processing of supplier data

Affected data: Data provided for the performance of the contract; any additional data for processing on the basis of your express consent.
Processing purpose: Contract execution, including inquiries, purchasing, quality assurance
Categories of recipients: Public authorities in the event of overriding legal provisions, e.g. tax office, customs. External service providers or other contractors, e.g. for data processing and hosting, accounting, payment processing. Other external bodies insofar as the data subject has given their consent or transmission is permitted for reasons of overriding interest.
Third country transfers: Processors outside the European Union may also be used in the context of contract performance, including email providers.alternatively -none-.
Data storage duration: The duration of data storage depends on the statutory retention obligations and is generally 10 years.

Further information and contacts

In addition, you can assert your rights to information, rectification or erasure or to restriction of processing or the exercise of your right to object to processing as well as the right to data portability at any time. Here you can contact us by e-mail or letter (see above for contact details). You also have the right to lodge a complaint with the data protection supervisory authority. Here you can contact us by e-mail or letter (see above for contact details). You also have the right to contact the data protection supervisory authority if you have a complaint.